Key storage method, apparatus and electronic device
By storing keys and key location records in different storage media, the problem of time-consuming initialization in traditional key storage schemes is solved, achieving efficient key management and improving the operational stability and market prospects of the equipment.
Patent Information
- Application Number
- CN202411374042.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-29
- Publication Date
- 2025-11-25
- Estimated Expiration
- 2044-09-29
AI Technical Summary
Traditional key storage schemes require traversing all keys during device initialization, which increases the time consumption, may affect the device initialization process, and may lead to unpredictable errors.
Different storage media are used to store the key and key location record respectively. The key is generated by a random number generation module and stored in an offset position of an unused storage area. The key location record is quickly stored using NOR flash and the key is stored using NAND flash, reducing traversal operations.
It achieves efficient and fast key storage and retrieval, avoids blocking during device initialization, improves storage and retrieval efficiency, and enhances product competitiveness.
Smart Images

Figure CN119483923B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of security technology, and in particular to a key storage method, apparatus, and electronic device. Background Technology
[0002] When developing secure storage products involving large-scale file encryption, there is a corresponding need for storing a large number of keys. Each file corresponds to a unique key, and the storage of these keys requires an efficient and fast management and storage solution. The key is stored during encryption and retrieved during decryption, with the retrieval process requiring quick location of the key corresponding to the index.
[0003] Traditional key storage schemes use an identifier (ID) + key combination for storage, stored on a single storage medium. When the device powers on, it needs to traverse all keys to identify unused space in the key storage area for storing new keys. However, the more keys are stored, the longer the traversal takes. If the traversal time is sufficiently long, it may affect the device initialization process, leading to unpredictable errors. Summary of the Invention
[0004] This invention provides a key storage method, apparatus, and electronic device to solve the defect that the time-consuming traversal affects the device initialization process and leads to unpredictable errors.
[0005] This invention provides a key storage method, comprising:
[0006] Obtain the key encryption command issued by the application;
[0007] Based on the key encryption instruction, the random number generation module is invoked to generate a key;
[0008] The key is stored in the offset position of the currently unused key storage area in the first storage medium, and the key position record of the key is stored in the offset position of the currently unused record storage area in the second storage medium; the first storage medium and the second storage medium are different.
[0009] According to a key storage method provided by the present invention, the key position record of the key is determined based on the offset position of the currently unused key storage area; each time the key is stored, the offset position of the currently unused key storage area is offset by a first target number; each time the key position record of the key is stored, the offset position of the currently unused record storage area is offset by a second target number.
[0010] According to a key storage method provided by the present invention, the method further includes:
[0011] Obtain the key decryption command issued by the application; the key decryption command carries the value of the key location record of the key;
[0012] Based on the value of the key location record of the key, determine the offset position of the key storage area in the first storage medium where the key is stored;
[0013] The key is read based on the offset position of the key storage area.
[0014] According to a key storage method provided by the present invention, before storing the key, the method further includes:
[0015] Based on the multiple sectors obtained by dividing the second storage medium, determine the offset position of the key location record of the latest stored key;
[0016] Based on the offset position, determine the offset position of the latest stored key;
[0017] Based on the offset position of the latest stored key, determine whether it is necessary to restore the offset position of the storage area of the record missed due to abnormal power failure;
[0018] In cases where it is necessary to recover the offset position of the record storage area missed due to abnormal power failure, the offset position of the missed record storage area is recovered.
[0019] If it is not necessary to restore the offset position of the record storage area missed due to abnormal power failure, the offset position of the missed record storage area will not be restored.
[0020] According to a key storage method provided by the present invention, determining the offset position of the key location record of the latest stored key based on multiple sectors obtained by dividing the second storage medium includes:
[0021] Based on any sector among the multiple sectors obtained by dividing the second storage medium, the array corresponding to the sector is traversed in units of a preset target byte.
[0022] If the offset position of the key position record corresponding to the target byte being traversed is not the offset position of the key position record of the latest stored key, then the judgment is repeated for each target byte after the target byte being traversed until the offset position of the key position record corresponding to the final target byte being traversed is the offset position of the key position record of the latest stored key.
[0023] The offset position of the key position record corresponding to the previous target byte of the final traversed target byte is determined as the offset position of the key position record of the latest stored key.
[0024] According to a key storage method provided by the present invention, the method further includes:
[0025] Determine whether the offset of the latest key position record is an integer multiple of the preset target number;
[0026] If the offset position of the latest key position record is an integer multiple of the preset target number, determine whether the offset position of the key position record of the previous sector is the offset position of the key position record of the latest stored key.
[0027] If the offset position of the key position record in the previous sector is not the offset position of the key position record of the latest stored key, then the offset position of the key position record in the previous sector is erased.
[0028] According to a key storage method provided by the present invention, the method further includes:
[0029] Based on the multiple sectors obtained by dividing the second storage medium, the key position record of at least one key is sequentially written into the first sector of the multiple sectors;
[0030] When the first sector is full, the key position records of the remaining keys in each key are sequentially written into the next sector of the first sector, and the process of writing the key position records in each sector is repeated until each sector is full.
[0031] If the last sector is full, re-execute the write to the first sector.
[0032] According to a key storage method provided by the present invention, the method further includes:
[0033] If the key position record is written to the next sector, the key position record written to the previous sector is erased.
[0034] The present invention also provides a key storage device, comprising:
[0035] The first acquisition module is used to acquire the key encryption instructions issued by the application.
[0036] The generation module is used to call the random number generation module to generate a key based on the key encryption instruction;
[0037] A storage module is used to store the key in an offset position of a currently unused key storage area in a first storage medium, and to store the key position record of the key in an offset position of a currently unused record storage area in a second storage medium; the first storage medium and the second storage medium are different.
[0038] The present invention also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement any of the key storage methods described above.
[0039] The present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the key storage method as described above.
[0040] The present invention also provides a computer program product, including a computer program that, when executed by a processor, implements any of the key storage methods described above.
[0041] The key storage method, apparatus, and electronic device provided by this invention obtain a key encryption instruction issued by an application program; based on the key encryption instruction, a random number generation module is invoked to generate a key; the key is stored in an offset position of a currently unused key storage area in a first storage medium, and the key position record of the key is stored in an offset position of a currently unused record storage area in a second storage medium; the first storage medium and the second storage medium are different. By storing the key and key position record separately in different storage media, efficient and fast key storage and retrieval are achieved when dealing with large-scale file encryption and decryption operations. It eliminates the need to traverse all keys, allowing the device to quickly find an idle key storage area without affecting the device initialization process or blocking the overall business process, thus preventing unpredictable errors. Simultaneously, it improves key storage and retrieval efficiency, greatly enhancing product competitiveness and market prospects. Attached Figure Description
[0042] To more clearly illustrate the technical solutions in this invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.
[0043] Figure 1 This is a flowchart illustrating the key storage method provided by the present invention.
[0044] Figure 2 This is a schematic diagram illustrating the relationship between the key location record and the offset position of the key storage area provided by the present invention.
[0045] Figure 3 This is a schematic diagram of the encryption business process provided by the present invention.
[0046] Figure 4 This is a schematic diagram of the decryption process provided by the present invention.
[0047] Figure 5 This is a schematic diagram of the power failure detection process provided by the present invention.
[0048] Figure 6 This is a schematic diagram of the key storage device provided by the present invention.
[0049] Figure 7 This is a schematic diagram of the structure of the electronic device provided by the present invention. Detailed Implementation
[0050] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this invention. All other embodiments obtained by those skilled in the art based on the embodiments of this invention without creative effort are within the scope of protection of this invention.
[0051] The following is combined Figures 1-5 The key storage method of the present invention is described.
[0052] Figure 1 This is a flowchart illustrating the key storage method provided by the present invention, as shown below. Figure 1 As shown, the method includes the following steps 101-103.
[0053] Step 101: Obtain the key encryption command issued by the application.
[0054] It should be noted that the key storage method provided by the present invention can be applied to scenarios involving the storage and management of large quantities of keys. The executing entity of the method can be a key storage device, such as an electronic device, or a control module in the key storage device for executing the key storage method.
[0055] Specifically, the application issues a key encryption instruction, and thus the key encryption instruction issued by the application can be obtained. The key encryption instruction is used to generate a key.
[0056] Step 102: Based on the key encryption instruction, call the random number generation module to generate a key.
[0057] Specifically, based on the key encryption instruction, the chip's random number generation module is invoked to generate a set of 16-byte random numbers, which are then used as the key.
[0058] Step 103: Store the key in the offset position of the currently unused key storage area in the first storage medium, and store the key position record of the key in the offset position of the currently unused record storage area in the second storage medium; the first storage medium and the second storage medium are different.
[0059] Specifically, after receiving the key encryption command from the application, following the "write key first, then write record" procedure, the key is stored in the offset position (g_key_offset) of the currently unused key storage area in the first storage medium, i.e., the key is written to the latest unused 16-byte space in the first storage medium. The key position record (pos) is stored in the offset position (g_pos_offset) of the currently unused record storage area in the second storage medium, i.e., the key position record is written to the latest unused 4-byte space in the second storage medium. The first and second storage media are different; for example, the first storage medium is NAND flash, and the second storage medium is NOR flash. After the key and key position record are stored (written), they are sent back to the application.
[0060] It's worth noting that flash memory is typically divided into NOR flash and NAND flash. NOR flash offers advantages such as high read speed and high reliability, but its disadvantages include smaller capacity and higher cost. NAND flash, on the other hand, has larger capacity and lower cost, but its data read speed is lower compared to NOR flash. Based on the characteristics of these different storage media, this invention employs a combination of both: the low-cost, high-capacity NAND flash is used to store the key, while the high-speed NOR flash is used to store the key location record.
[0061] Optionally, the key position record of the key is determined based on the offset position of the currently unused key storage area; each time the key is stored, the offset position of the currently unused key storage area is offset by a first target number; each time the key position record of the key is stored, the offset position of the currently unused record storage area is offset by a second target number.
[0062] Specifically, the key position record (pos) of the key is determined based on the offset position of the currently unused key storage area (g_key_offset). The value of the key position record (pos) is the key ID, which is the offset position of the currently unused key storage area (g_key_offset) divided by 16, i.e., (g_key_offset / 16). The write positions of the key and the key position record are controlled by two global variables (g_key_offset and g_pos_offset), where g_key_offset represents the offset position of the unused record storage address corresponding to the current key (key), and g_pos_offset represents the offset position of the unused storage address corresponding to the current key position record (pos). These two variables are assigned values during device initialization after a power-down detection process and their lifecycle continues throughout the entire device operation. Each time a key is written, the offset position of the currently unused key storage area is offset by the first target number. For example, if the first target number is 16, then g_key_offset is incremented by 16. Each time a record is written, the offset position of the currently unused record storage area is offset by the second target number. For example, if the first target number is 4, then g_pos_offset is incremented by 4.
[0063] Figure 2 This is a schematic diagram illustrating the relationship between the key location record and the offset position of the key storage area provided by the present invention, as shown below. Figure 2 As shown, there is no necessary connection between the unused record storage address offset (g_pos_offset) and the currently unused key storage area offset (g_key_offset). They are independent offset positions. The only causal relationship is the value ID stored in the key position record (pos) of the key, which is ID = g_key_offset / 16. That is, the latest pos records the offset position of the latest key. However, pos and key are not necessarily strictly one-to-one. pos only needs to record the offset position of the latest key so that the device can quickly find the offset of the usable key storage area when it is powered on again. In other words, it is not necessary to write to pos synchronously every time a key is written. This can be further optimized. For example, in order to reduce the number of writes to NOR flash, a timed or quantitative pos writing method can be designed. Taking quantitative pos writing as an example, a pos writing operation is triggered only once every 10 key writes. That is, pos0 stores ID0 and pos1 stores ID9.
[0064] The number of keys that the device can write is limited by a pre-agreed limit. When this limit is exceeded, the device will respond to the initiator of the instruction (i.e., the application) with a message indicating insufficient key capacity, signifying that key storage is no longer supported. There is no limit to the number of key location records that can be written; the actual number of keys will prevail.
[0065] The key storage method provided by this invention involves obtaining a key encryption command issued by an application; generating a key based on the key encryption command by calling a random number generation module; storing the key in an offset position of an unused key storage area in a first storage medium, and storing the key position record in an offset position of an unused record storage area in a second storage medium; the first and second storage media are different. By storing the key and key position record separately in different storage media, efficient and fast key storage and retrieval are achieved when dealing with large-scale file encryption and decryption operations. This method allows the device to quickly find an idle key storage area without traversing all keys, without affecting the device initialization process or blocking the overall business process, thus preventing unpredictable errors. It also improves key storage and retrieval efficiency, greatly enhancing product competitiveness and market prospects.
[0066] Figure 3 This is a schematic diagram of the encryption business process provided by the present invention, such as... Figure 3 As shown, it includes steps 301-306.
[0067] Step 301: The application sends a key encryption command.
[0068] Step 302: Call the random number generation module to generate a set of 16-byte random numbers, and use this random number as the key.
[0069] Step 303: Write the key into the NAND flash corresponding to g_key_offset.
[0070] Step 304: Write g_key_offset / 16 into the NOR flash corresponding to g_pos_offset.
[0071] Step 305: Return g_key_offset / 16 and the key to the application.
[0072] Step 306: Each time the key is written, g_key_offset is offset by 16 bytes; each time the key position record is written, g_pos_offset is offset by 4 bytes.
[0073] Optionally, the method further includes:
[0074] Obtain the key decryption instruction issued by the application; the key decryption instruction carries the value of the key location record of the key; based on the value of the key location record of the key, determine the offset position of the key storage area in the first storage medium where the key is stored; based on the offset position of the key storage area, read the key.
[0075] Specifically, the application issues a key decryption command, which carries the value of the key's key location record. Therefore, the key decryption command issued by the application can be retrieved. Based on the value (ID) of the key's key location record (pos), the decryption command can be obtained through the ID. 16 can determine the key storage area offset (key_offset) in the first storage medium; then, based on the key storage area offset, the key can be read by the base address + key storage area offset and applied to the decryption business.
[0076] Figure 4 This is a schematic diagram of the decryption process provided by the present invention, such as... Figure 4 As shown, it includes steps 401-404.
[0077] Step 401: Obtain the key decryption command issued by the application. The key decryption command carries the value of the key location record of the key. The value of the key location record of the key is the key ID. The key ID is the offset position of the key storage area corresponding to the key when storing the key based on the key encryption command divided by 16, that is, g_key_offset / 16.
[0078] Step 402: Based on the key ID, determine the key storage area offset position key_offset in the first storage medium where the key is stored.
[0079] Step 403: Based on the key storage area offset position key_offset, read the key using the base address + key storage area offset position key_offset.
[0080] Step 404: Configure the key and decrypt the business process.
[0081] Optionally, before storing the key, the method further includes:
[0082] (1) Based on the multiple sectors obtained by dividing the second storage medium, determine the offset position of the key location record of the latest stored key.
[0083] It should be noted that this application involves frequent writes to flash storage. If an abnormal power failure occurs during the write process, it may lead to errors in the data storage process. Based on this deficiency, this application proposes an abnormal power failure handling scheme. Power failure detection is processed during device initialization. Because it is necessary to find the latest key position (pos) record, a large number of flash read operations are involved, which will affect the system startup speed. Therefore, when reading pos, data is read in sectors rather than in individual pos. The data of one sector is read and then stored in the Random Access Memory (RAM) as an array before logical judgment is performed. This greatly reduces the number of reads of NOR flash, improves the overall read speed, and speeds up the device initialization process.
[0084] Specifically, the power failure detection process mainly includes the following steps: the second storage medium (nor flash) is divided into multiple sectors, and based on the multiple sectors, the offset position (last_pos_offset) of the key position record of the latest stored key can be determined.
[0085] (2) Determine the offset position of the latest stored key based on the offset position.
[0086] Specifically, based on the offset position, the value of the key position record of the most recently stored key can be read. The value of the key position record of the most recently stored key corresponds to the offset position (last_key_offset) of the most recently stored key, that is, the offset position of the key that was last written. Then, through last_key_offset... The 16+ base address can determine the most recently stored key.
[0087] (3) Based on the offset position of the latest stored key, determine whether it is necessary to restore the offset position of the storage area of the record that was missed due to abnormal power failure.
[0088] Specifically, because the key is written first and then the key position record is written, the following abnormal situation may occur during the writing process: Power failure occurs before the new key and / or the new key position record is written, and the latest pos record found is actually the old marker from the previous write, i.e., the old key position record. To address this issue, the following strategy is used: Based on the offset position (last_key_offset) of the latest stored key, check if the key corresponding to last_key_offset + 16 bytes exists. This can determine whether it is necessary to recover the record storage area offset position missed due to the abnormal power failure.
[0089] (4) In cases where it is necessary to restore the offset position of the record storage area that was missed due to abnormal power failure, restore the offset position of the missed record storage area.
[0090] Specifically, if the key exists, it indicates that there was a pos omission caused by an abnormal power outage. It is necessary to restore the offset position of the record storage area that was missed due to the abnormal power outage. To restore the offset position of the missed record storage area, we continue to traverse the key corresponding to the last_key_offset+16+16 bytes until there is no key at the latest last_key_offset' position, and record the latest last_key_offset'. At this time, the pos value calculated by the latest last_key_offset' (i.e., pos=last_key_offset' / 16) is updated and written to the NOR flash.
[0091] (5) If it is not necessary to restore the offset position of the record storage area that was missed due to abnormal power failure, the offset position of the missed record storage area shall not be restored.
[0092] Specifically, if the key does not exist, it means that there is no missing POS due to abnormal power loss. Therefore, it is not necessary to restore the offset position of the missing record storage area due to abnormal power loss, and the offset position of the missing record storage area will not be restored.
[0093] Optionally, determining the offset position of the key location record of the most recently stored key based on the multiple sectors obtained by dividing the second storage medium includes:
[0094] (1-1) Based on any sector among the multiple sectors obtained by dividing the second storage medium, traverse the array corresponding to the sector in units of a preset target byte.
[0095] Specifically, based on any sector among the multiple sectors obtained by dividing the second storage medium, all key position records recorded in that sector are read into an array, and the array corresponding to that sector is traversed in units of a preset target byte. For example, if the preset target byte is 4 bytes, the entire array is traversed in units of 4 bytes.
[0096] Since the initial value of flash storage is all 1s, this characteristic can be used to determine the pos record. When the value of pos is 0xFFFFFFFF, it means that there is no pos record here, that is, the previous 4 bytes are the latest pos record. The latest pos record stored in the array can be found in this way.
[0097] (1-2) If the offset position of the key position record corresponding to the target byte being traversed is not the offset position of the key position record of the latest stored key, the judgment is repeated for each target byte after the target byte being traversed until the offset position of the key position record corresponding to the target byte being traversed is the offset position of the key position record of the latest stored key.
[0098] Specifically, the preset offset position of the latest stored key's key position record, last_pos_offset=0xFFFFFFFF, indicates the offset position of the currently traversed latest stored key's key position record. 0xFFFFFFFF is an invalid value, meaning no latest pos record was found. If the offset position of the key position record corresponding to the currently traversed target byte is not the preset offset position of the latest stored key's key position record, it means a key position record exists, but it does not necessarily mean it is the latest key position record. It is necessary to check the next target byte after the currently traversed target byte, and repeat this process for each target byte after the currently traversed target byte, until the offset position of the key position record corresponding to the final traversed target byte is the preset offset position of the latest stored key's key position record.
[0099] (1-3) The offset position of the key position record corresponding to the previous target byte of the final traversed target byte is determined as the offset position of the key position record of the latest stored key.
[0100] Specifically, the offset position of the key position record corresponding to the previous target byte of the final traversed target byte can be determined as the offset position of the key position record of the latest stored key.
[0101] Optionally, if the offset of the key position record corresponding to the target byte being traversed is the offset of the key position record of the latest stored key, it means that no key position record has been found in the current sector, that is, the pos record has never been found. In fact, the first target byte (4 bytes) is 0xFFFFFFFF. According to the pos writing mechanism, the entire array is 0xFFFFFFFF. The remaining 4092 bytes do not need to be traversed again. The array can be updated by directly reading the 4K data of the next sector and traversing again.
[0102] Optionally, the method further includes:
[0103] Determine whether the offset position of the latest key position record is an integer multiple of the preset target number; if the offset position of the latest key position record is an integer multiple of the preset target number, determine whether the offset position of the key position record of the previous sector is the offset position of the preset latest stored key; if the offset position of the key position record of the previous sector is not the offset position of the preset latest stored key, erase the offset position of the key position record of the previous sector.
[0104] Specifically, after writing a sector (4096 bytes), writing a new sector will erase the entire position of the previous sector. An abnormal power outage can lead to a special situation: after the new position is written to the new sector, the data in the previous sector has not yet been erased when the power goes out, leaving the previous sector in an unerased state. This will cause unexpected errors when the sector is used again. Therefore, in the power outage detection, it is necessary to determine whether the offset position of the latest key position record, last_pos_offset, is an integer multiple of the preset target number. The preset target number is 4096, so it is necessary to determine whether it is an integer multiple of 4096.
[0105] If the offset of the latest key position record is an integer multiple of the preset target number, it means that the current record is in the first target byte (4 bytes) of the new sector. It is necessary to determine whether the offset of the key position record in the previous sector is the same as the offset of the latest stored key position record, i.e., whether the offset of the key position record in the previous sector is 0xFFFFFFFF. If the offset of the key position record in the previous sector is not the same as the offset of the latest stored key position record, the offset of the key position record in the previous sector should be erased. If the offset of the key position record in the previous sector is the same as the offset of the latest stored key position record, no processing is required.
[0106] Figure 5 This is a schematic diagram of the power failure detection process provided by the present invention, as shown below. Figure 5 As shown, steps 501-513 are included.
[0107] Step 501: Device initialization.
[0108] Step 502: Read the fixed storage area of the NOR flash, divide the NOR flash into multiple sectors and traverse them.
[0109] Step 503: Determine the offset position of the key location record of the latest stored key.
[0110] Step 504: Determine the offset position of the latest stored key based on the offset position.
[0111] Step 505: Based on the offset position of the latest stored key, read the value of the key position record of the latest stored key, and then based on the value of the key position record of the latest stored key corresponding to the offset position and base address of the latest stored key, read the key in the NAND flash.
[0112] Step 506: Determine if the key corresponding to last_key_offset+16 bytes exists. If the key corresponding to last_key_offset+16 bytes exists, proceed to step 507; if the key corresponding to last_key_offset+16 bytes does not exist, proceed to step 510.
[0113] Step 507: This indicates that there is a missing POS record due to an abnormal power outage, and it is necessary to restore the offset position of the storage area of the record that was missed due to the abnormal power outage.
[0114] Step 508: Start reading the key from last_key_offset+16 until there is no key at the latest last_key_offset position, and record the latest last_key_offset.
[0115] Step 509: Update the pos value calculated using the latest 'last_key_offset' and write it to the NOR flash.
[0116] Step 510: Determine whether the offset of the key position record corresponding to the target byte being traversed is an integer multiple of 4096. If the offset of the key position record corresponding to the target byte being traversed is an integer multiple of 4096, proceed to step 511; if the offset of the key position record corresponding to the target byte being traversed is not an integer multiple of 4096, proceed to step 513.
[0117] Step 511: Determine whether the offset of the key position record in the previous sector is the offset of the latest stored key position record (0xFFFFFFFF), that is, determine whether the first 4 bytes of the previous sector are 0xFFFFFFFF. If the offset of the key position record in the previous sector is not the offset of the latest stored key position record, proceed to step 512; if the offset of the key position record in the previous sector is the offset of the latest stored key position record, proceed to step 513.
[0118] Step 512: If the first 4 bytes of the previous sector contain a record and the previous sector is full and has not been erased, then erase the offset position of the key location record of the entire previous sector, taking the previous sector as the unit.
[0119] Step 513: No further processing required. Proceed to the normal procedure.
[0120] Optionally, the method further includes:
[0121] Based on the multiple sectors obtained by dividing the second storage medium, the key position record of at least one key is sequentially written into the first sector of the multiple sectors; when the first sector is full, the key position records of the remaining keys in each key are sequentially written into the next sector of the first sector, and the process of writing the key position record in each sector is repeated until each sector is full; when the last sector is full, the process of writing the first sector is repeated.
[0122] It should be noted that the purpose of setting a 4-byte variable `pos` to record the key offset position is to facilitate direct reading of the variable's value during the next device startup, allowing for quick location of unused space in the key storage area without having to traverse the key storage area again. However, if this variable is written to a fixed location in the NOR flash, due to the large number of write operations involved, it will cause repeated erasure and writing of certain sectors of the NOR flash, significantly reducing its lifespan compared to other sectors. Therefore, for this reason, a scheme to even out wear on the NOR flash memory is proposed.
[0123] Specifically, based on multiple sectors obtained from the second storage medium, for example, based on NOR flash, a contiguous 1MB NOR flash storage space is allocated and divided into 256 4KB sectors for cyclical use. The key position record of at least one key is sequentially written to the first sector of the multiple sectors. After writing the key position record (pos record), g_pos_offset is shifted forward by 4 bytes until the entire first sector is completely filled. When the first sector is full, the key position records of the remaining keys are sequentially written to the next sector of the first sector, and this process of writing key position records in each sector is repeated until each sector is full. When the last sector is full, the process of writing to the first sector is repeated, i.e., writing starts again from the first sector. This cycle repeats, achieving wear leveling of the pos storage area to a certain extent. Compared to writing pos at fixed positions, this method can minimize the generation of bad blocks and increase the overall lifespan of the product. The above parameters can be flexibly changed according to actual needs and application scenarios.
[0124] Optionally, the method further includes:
[0125] If the key position record is written to the next sector, the key position record written to the previous sector is erased.
[0126] Specifically, when writing a key position record to the next sector, for example, after writing the first key position record to the next sector, the key position record written in the previous sector is erased, that is, the entire contents of the previous sector are erased.
[0127] It should be noted that the wear leveling strategy only applies to the NOR flash storage portion, because the NAND flash write key is continuously incremented until it reaches the agreed maximum value, and there will be no repeated erasure or writing, so no processing is required.
[0128] This invention proposes a design scheme for wear equalization and power failure detection, which increases the stability and service life of the product, facilitates meeting customer needs, enriches the application scenarios of the product, and is conducive to the market promotion of the product.
[0129] The key storage device provided by the present invention is described below. The key storage device described below can be referred to in correspondence with the key storage method described above.
[0130] Figure 6 This is a schematic diagram of the key storage device provided by the present invention, as shown below. Figure 6 As shown, the key storage device 600 includes: a first acquisition module 601, a generation module 602, and a storage module 603; wherein,
[0131] The first acquisition module 601 is used to acquire the key encryption instruction issued by the application.
[0132] The generation module 602 is used to call the random number generation module to generate a key based on the key encryption instruction;
[0133] Storage module 603 is used to store the key in the offset position of the currently unused key storage area in the first storage medium, and to store the key position record of the key in the offset position of the currently unused record storage area in the second storage medium; the first storage medium and the second storage medium are different.
[0134] The key storage device provided by this invention obtains a key encryption command issued by an application; based on the key encryption command, it calls a random number generation module to generate a key; it stores the key in an offset position of an unused key storage area in a first storage medium, and stores the key position record in an offset position of an unused record storage area in a second storage medium; the first storage medium and the second storage medium are different. By storing the key and key position record separately in different storage media, efficient and fast key storage and retrieval are achieved when dealing with large-scale file encryption and decryption operations. It allows the device to quickly find an idle key storage area without traversing all keys, without affecting the device initialization process or blocking the overall business process, thus preventing unpredictable errors. Simultaneously, it improves key storage and retrieval efficiency, greatly enhancing product competitiveness and market prospects.
[0135] Optionally, the key position record of the key is determined based on the offset position of the currently unused key storage area; each time the key is stored, the offset position of the currently unused key storage area is offset by a first target number; each time the key position record of the key is stored, the offset position of the currently unused record storage area is offset by a second target number.
[0136] Optionally, the key storage device 600 further includes:
[0137] The second acquisition module is used to acquire the key decryption instruction issued by the application; the key decryption instruction carries the value of the key location record of the key;
[0138] The first determining module is used to determine the offset position of the key storage area in the first storage medium based on the value of the key location record of the key;
[0139] The reading module is used to read the key based on the offset position of the key storage area.
[0140] Optionally, the key storage device 600 further includes:
[0141] The second determining module is used to determine the offset position of the key position record of the latest stored key based on the multiple sectors obtained by dividing the second storage medium.
[0142] The third determining module is used to determine the offset position of the latest stored key based on the offset position;
[0143] The first judgment module is used to determine whether it is necessary to restore the offset position of the record storage area missed due to abnormal power failure based on the offset position of the latest stored key.
[0144] The first recovery module is used to recover the offset position of the missing record storage area when it is necessary to recover the offset position of the record storage area missed due to abnormal power failure.
[0145] The second recovery module is used to prevent the recovery of the offset positions of the missing record storage areas when it is not necessary to recover the offset positions of the record storage areas missed due to abnormal power failure.
[0146] Optionally, the second determining module is specifically used for:
[0147] Based on any sector among the multiple sectors obtained by dividing the second storage medium, the array corresponding to the sector is traversed in units of a preset target byte.
[0148] If the offset position of the key position record corresponding to the target byte being traversed is not the offset position of the key position record of the latest stored key, then the judgment is repeated for each target byte after the target byte being traversed until the offset position of the key position record corresponding to the final target byte being traversed is the offset position of the key position record of the latest stored key.
[0149] The offset position of the key position record corresponding to the previous target byte of the final traversed target byte is determined as the offset position of the key position record of the latest stored key.
[0150] Optionally, the key storage device 600 further includes:
[0151] The second judgment module is used to determine whether the offset position of the latest key position record is an integer multiple of the preset target number;
[0152] The fourth determining module is used to determine whether the offset position of the key position record of the previous sector is the offset position of the key position record of the latest key when the offset position of the latest key position record is an integer multiple of the preset target number.
[0153] The first erasure module is used to erase the offset position of the key position record of the previous sector when the offset position of the key position record of the previous sector is not the offset position of the key position record of the latest stored key.
[0154] Optionally, the key storage device 600 further includes:
[0155] The first writing module is used to sequentially write the key position record of at least one key into the first sector of the plurality of sectors based on the plurality of sectors obtained by dividing the second storage medium.
[0156] The second writing module is used to, when the first sector is full, sequentially write the key position records of the remaining keys in each of the keys into the next sector of the first sector, and repeat the process of writing the key position records in each sector until each sector is full.
[0157] The re-execution module is used to re-execute the writing of the first sector if the last sector is full.
[0158] Optionally, the key storage device 600 further includes:
[0159] The second erasure module is used to erase the key position record written in the previous sector when the next sector begins to write the key position record.
[0160] Figure 7 This is a schematic diagram of the physical structure of an electronic device provided by the present invention, such as... Figure 7 As shown, the electronic device 700 may include a processor 710, a communications interface 720, a memory 730, and a communication bus 740, wherein the processor 710, communications interface 720, and memory 730 communicate with each other via the communication bus 740. The processor 710 can call logical instructions in the memory 730 to execute a key storage method, which includes: obtaining a key encryption instruction issued by an application program; generating a key based on the key encryption instruction by calling a random number generation module; storing the key in an offset position of a currently unused key storage area in a first storage medium, and storing the key position record in an offset position of a currently unused record storage area in a second storage medium; the first storage medium and the second storage medium are different.
[0161] Furthermore, the logical instructions in the aforementioned memory 730 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, essentially, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0162] On the other hand, the present invention also provides a computer program product, which includes a computer program that can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the key storage method provided by the above methods. The method includes: obtaining a key encryption instruction issued by an application program; generating a key by calling a random number generation module based on the key encryption instruction; storing the key in an offset position of a currently unused key storage area in a first storage medium, and storing the key position record of the key in an offset position of a currently unused record storage area in a second storage medium; the first storage medium and the second storage medium are different.
[0163] In another aspect, the present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon. When executed by a processor, the computer program is implemented to perform the key storage method provided by the above methods. The method includes: obtaining a key encryption instruction issued by an application program; generating a key by calling a random number generation module based on the key encryption instruction; storing the key in an offset position of a currently unused key storage area in a first storage medium, and storing the key position record of the key in an offset position of a currently unused record storage area in a second storage medium; wherein the first storage medium and the second storage medium are different.
[0164] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.
[0165] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.
[0166] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A key storage method, characterized in that, include: Obtain the key encryption command issued by the application; Based on the key encryption instruction, the random number generation module is invoked to generate a key; The key is stored in the offset position of the currently unused key storage area in the first storage medium, and the key position record of the key is stored in the offset position of the currently unused record storage area in the second storage medium; The first storage medium and the second storage medium are different; Before storing the key, the method further includes: Based on the multiple sectors obtained by dividing the second storage medium, determine the offset position of the key location record of the latest stored key; Based on the offset position, determine the offset position of the latest stored key; Based on the offset position of the latest stored key, determine whether it is necessary to restore the offset position of the record storage area missed due to abnormal power failure; In cases where it is necessary to recover the offset position of the record storage area missed due to abnormal power failure, the offset position of the missed record storage area is recovered. If it is not necessary to restore the offset position of the record storage area missed due to abnormal power failure, the offset position of the missed record storage area will not be restored.
2. The key storage method according to claim 1, characterized in that, The key position record of the key is determined based on the offset position of the currently unused key storage area; each time the key is stored, the offset position of the currently unused key storage area is offset by a first target number; each time the key position record of the key is stored, the offset position of the currently unused record storage area is offset by a second target number.
3. The key storage method according to claim 1, characterized in that, The method further includes: Obtain the key decryption command issued by the application; the key decryption command carries the value of the key location record of the key; Based on the value of the key location record of the key, determine the offset position of the key storage area in the first storage medium where the key is stored; The key is read based on the offset position of the key storage area.
4. The key storage method according to claim 1, characterized in that, The step of determining the offset position of the key location record of the latest stored key based on multiple sectors obtained by dividing the second storage medium includes: Based on any sector among the multiple sectors obtained by dividing the second storage medium, the array corresponding to the sector is traversed in units of a preset target byte. If the offset position of the key position record corresponding to the target byte being traversed is not the offset position of the key position record of the latest stored key, then the judgment is repeated for each target byte after the target byte being traversed until the offset position of the key position record corresponding to the final target byte being traversed is the offset position of the key position record of the latest stored key. The offset position of the key position record corresponding to the previous target byte of the final traversed target byte is determined as the offset position of the key position record of the latest stored key.
5. The key storage method according to claim 4, characterized in that, The method further includes: Determine whether the offset of the latest key position record is an integer multiple of the preset target number; If the offset position of the latest key position record is an integer multiple of the preset target number, determine whether the offset position of the key position record of the previous sector is the offset position of the key position record of the latest stored key. If the offset position of the key position record in the previous sector is not the offset position of the key position record of the latest stored key, then the offset position of the key position record in the previous sector is erased.
6. The key storage method according to claim 1, characterized in that, The method further includes: Based on the multiple sectors obtained by dividing the second storage medium, the key position record of at least one key is sequentially written into the first sector of the multiple sectors; When the first sector is full, the key position records of the remaining keys in each key are sequentially written into the next sector of the first sector, and the process of writing the key position records in each sector is repeated until each sector is full. If the last sector is full, re-execute the write to the first sector.
7. The key storage method according to claim 6, characterized in that, The method further includes: If the key position record is written to the next sector, the key position record written to the previous sector is erased.
8. A key storage device, characterized in that, include: The first acquisition module is used to acquire the key encryption instructions issued by the application. The generation module is used to call the random number generation module to generate a key based on the key encryption instruction; The storage module is used to store the key in the offset position of the currently unused key storage area in the first storage medium, and to store the key position record of the key in the offset position of the currently unused record storage area in the second storage medium; The first storage medium and the second storage medium are different; Before storing the key, the following is also included: The second determining module is used to determine the offset position of the key position record of the latest stored key based on the multiple sectors obtained by dividing the second storage medium. The third determining module is used to determine the offset position of the latest stored key based on the offset position; The first judgment module is used to determine whether it is necessary to restore the offset position of the record storage area missed due to abnormal power failure based on the offset position of the latest stored key. The first recovery module is used to recover the offset position of the missing record storage area when it is necessary to recover the offset position of the record storage area missed due to abnormal power failure. The second recovery module is used to prevent the recovery of the offset positions of the missing record storage areas when it is not necessary to recover the offset positions of the record storage areas missed due to abnormal power failure.
9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the key storage method as described in any one of claims 1 to 7.
Citation Information
Patent Citations
Online security key protection method and system
CN106982186A
Processing devices to perform a key value lookup instruction
CN108475199A